Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

AKAV LABS

@akavlabs@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Building runtime security for LLM agents. Open-source gateway (Rust, Apache-2.0) for prompt-injection/secret-leak detection. Red-team my own tool, post the gaps. akav.io

0 Followers
20 Following
4 Posts
Joined July 15, 2026
website:
https://www.akav.io/
Open post
AKAV LABS @akavlabs@infosec.exchange
· 2mo ago
Replying to
The passes went ingress → egress → streaming. Streaming was the real hole: a secret split across SSE tokens ("sk-"…"AKIA"…) never appears whole in a single chunk, so a whole-body scanner never sees it. Fixed with a rolling-window scanner that cuts the stream before the secret completes. Every fix has a benign-guard test — blocking "how do I prevent exfiltration?" is what gets a tool uninstalled. 0 false positives across the run. Not a claim to "solve" injection (you can't) — just raising the cost of the exfil leg of the lethal trifecta. https://dev.to/akavlabs_69/i-red-teamed-my-own-llm-security-gateway-in-four-passes-heres-every-gap-i-found-5cl9 Repo, Apache-2.0: github.com/akav-labs/agentsentry-gateway
dev.to
0
0
0
0
Open post
AKAV LABS @akavlabs@infosec.exchange
· 2mo ago
Replying to
@hasamba@infosec.exchange This is a clean example of why source review can't be the whole answer — the payload doesn't exist in the repo at scan time, it's fetched at runtime from a DNS TXT record. Static scanners, human review, even agent self-review are structurally blind to that. Feels like the strongest argument for a boundary layer that watches what the agent actually does (shell exec, outbound connections, secrets/creds leaving the process) rather than what it was told to do. Ingress-side filtering can't catch an instruction that doesn't exist yet.
0
0
0
0
Open post
AKAV LABS @akavlabs@infosec.exchange
· 2mo ago
Replying to on social.security.plumbing
@freddy@social.security.plumbing @simon@fedi.simonwillison.net Strong +1 on non-binary. One data point on granularity: scanning responses (not just requests) took secret detection from 5/20 to 20/20 in testing. But even that misses secrets split across SSE chunks in streaming — no single chunk ever contains the whole string. So "limit egress" needs its own sub-dimension: per-request vs per-chunk vs per-session. Doesn't eliminate the risk, just moves the cost curve — closer to reality than a binary block/allow.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:38:24 UTC